github.com/boostsecurityio/poutine
v1.1.6
#2621 most downloaded on Go modules
boostsecurityio/poutine
What this package is like to depend on
Last release 1 months ago
09 Jul 2026
Release timing varies
gaps range from 8 days to 4 months
Some releases are documented
notes for 10 of 40 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
93 releases · first in 2024
29 releases in the last 12 months
see the full history below
Release timeline
93 releases · Apr 2024 to Jul 2026Releases
latest 60 of 93-
v1.1.7-0.20260709184029-bd4c1f86fe8c09 Jul 2026 pre-releaseNothing published for this version
-
v1.1.622 May 2026Release notes
Open source →What's Changed
- skip persisting with version check when running in ci by @SUSTAPLE117 in #439
Full Changelog: v1.1.5...v1.1.6
-
v1.1.522 May 2026Release notes
Open source →What's Changed
- Fix Default Branch Detection For Analysis by @SUSTAPLE117 in #437
- add version check call to poutine by @SUSTAPLE117 in #438
Full Changelog: v1.1.4...v1.1.5
-
v1.1.417 Apr 2026Release notes
Open source →What's Changed
- Reworked Refs Resolution by @SUSTAPLE117 in #423
- feat(config): discover .github/poutine.yml as a config path by @graelo in #424
New Contributors
Full Changelog: v1.1.3...v1.1.4
-
v1.1.4-0.20260415210901-f5f1cd166bf215 Apr 2026 pre-releaseNothing published for this version
-
v1.1.308 Apr 2026Release notes
Open source →Changelog for
poutinev1.1.3 🎉This release focuses on core engine improvements, stability fixes, and modernization of the toolchain. The biggest shift is the move away from exec-based Git operations toward a fully in-memory model using
go-git, along with improved resiliency and observability during analysis.
Major Improvements 🌟🌟
-
⚡ In-Memory Git with
go-gitv6: Replaced exec-based Git operations withgo-gitusing in-memory storage. This significantly improves performance, portability, and reduces reliance on system binaries, by @SUSTAPLE117.
(#400) -
🛡️ Resilient Repository Batch Fetching: Improved robustness of repository batch fetching, reducing failures during large-scale analysis operations, by @SUSTAPLE117.
(#399) -
📊 Analysis Progress Monitoring Improvements: Enhanced visibility into analysis progress, making long-running operations easier to track and debug, by @SUSTAPLE117.
(#419)
Improvements 🔧
-
🧪 Snapshot Testing Added: Introduced snapshot testing to improve regression detection and testing confidence, by @SUSTAPLE117.
(#401) -
⚙️ Go 1.26 Upgrade + Dependency Refresh: Upgraded to Go 1.26 and refreshed dependencies for improved performance and compatibility, by @SUSTAPLE117.
(#412) -
🔐 Improved Rule Handling for GitHub Actions: Configured
skipactions to be ignored for thegithub_action_from_unverified_creator_usedrule, improving rule accuracy, by @mbarbero.
(#398) -
📦 Goreleaser Configuration Updates: Updated release configuration and tooling for improved build and distribution workflows, by @SUSTAPLE117.
(#417), (#418)
Bug Fixes 🐛
-
🐳 Docker Image Parsing Fixes: Fixed issues with Docker image parsing and purl generation, by @SUSTAPLE117.
(#413) -
📄 YAML Parsing Fixes: Resolved YAML parsing errors affecting analysis reliability, by @SUSTAPLE117.
(#414) -
🔑 GitHub Fine-Grained PAT Compatibility: Fixed organization repository listing failures when using fine-grained tokens without
Issues:Read, by @fproulx-boostsecurity.
(#415) -
🧾 SARIF Taxonomy GUID Fix: Corrected SARIF taxonomy GUID issues to ensure proper report compatibility, by @SUSTAPLE117.
(#416)
Dependency Updates ⬆️
GitHub Actions
- Updated
github/codeql-actionfrom3.30.5to4.31.2. (#370) - Updated
ossf/scorecard-actionfrom2.4.2to2.4.3. (#371) - Updated
step-security/harden-runnerfrom2.13.0to2.13.1. (#375) - Updated
actions/upload-artifactfrom4.6.2to5.0.0. (#376) - Updated
actions/setup-gofrom5.5.0to6.4.0. (#403) - Updated
goreleaser/goreleaser-actionfrom6.4.0to7.0.0. (#411) - Updated
actions/deploy-pagesfrom4.0.5to5.0.0. (#410) - Updated
actions/checkoutfrom5.0.0to6.0.2. (#408) - Updated
sigstore/cosign-installeracross versions3.9.2 → 4.0.0 → 4.1.1. (#377), (#405)
Go Modules
- Updated
gitlab.com/gitlab-org/api/client-gofrom0.151.0to0.157.1. (#369) - Updated
github.com/open-policy-agent/opafrom1.9.0to1.10.0. (#372) - Updated
github.com/mark3labs/mcp-gofrom0.41.1to0.42.0. (#373) - Updated
golang.org/x/oauth2from0.31.0to0.32.0. (#374) - Updated
golang.org/x/cryptofrom0.42.0to0.45.0. (#380)
Full Changelog 📜
For a detailed view of all changes, see the full changelog.
-
-
v1.1.206 Apr 2026Release notes
Open source →What's Changed
- build(deps): bump gitlab.com/gitlab-org/api/client-go from 0.151.0 to 0.157.1 by @dependabot[bot] in #369
- build(deps): bump github/codeql-action from 3.30.5 to 4.31.2 by @dependabot[bot] in #370
- build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 by @dependabot[bot] in #371
- build(deps): bump github.com/open-policy-agent/opa from 1.9.0 to 1.10.0 by @dependabot[bot] in #372
- build(deps): bump github.com/mark3labs/mcp-go from 0.41.1 to 0.42.0 by @dependabot[bot] in #373
- build(deps): bump step-security/harden-runner from 2.13.0 to 2.13.1 by @dependabot[bot] in #375
- build(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by @dependabot[bot] in #376
- build(deps): bump sigstore/cosign-installer from 3.9.2 to 4.0.0 by @dependabot[bot] in #377
- build(deps): bump golang.org/x/oauth2 from 0.31.0 to 0.32.0 by @dependabot[bot] in #374
- build(deps): bump golang.org/x/crypto from 0.42.0 to 0.45.0 in the go_modules group across 1 directory by @dependabot[bot] in #380
- Add Resiliency to Repo Batch Fetch by @SUSTAPLE117 in #399
- Configured 'skip' actions for rule 'github_action_from_unverified_creator_used' are ignored by @mbarbero in #398
- Add Snapshot Testing by @SUSTAPLE117 in #401
- build(deps): bump actions/setup-go from 5.5.0 to 6.4.0 by @dependabot[bot] in #403
- build(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.1 by @dependabot[bot] in #405
- build(deps): bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 by @dependabot[bot] in #411
- build(deps): bump actions/deploy-pages from 4.0.5 to 5.0.0 by @dependabot[bot] in #410
- feat: replace exec-based git with go-git v6 in-memory storage by @SUSTAPLE117 in #400
- Go 1.26 + Deps Upgrade by @SUSTAPLE117 in #412
- fix docker image parsing and purls by @SUSTAPLE117 in #413
- Fix Yaml Parse Errors by @SUSTAPLE117 in #414
- build(deps): bump actions/checkout from 5.0.0 to 6.0.2 by @dependabot[bot] in #408
- fix(github): org repo listing fails with fine-grained PATs lacking Issues:Read by @fproulx-boostsecurity in #415
- Fix SARIF Taxonomy GUID by @SUSTAPLE117 in #416
- Updated Goreleaser Config by @SUSTAPLE117 in #417
- updated goreleaser version by @SUSTAPLE117 in #418
Full Changelog: v1.0.8...v1.1.2
-
v1.1.006 Apr 2026Nothing published for this version
-
v1.0.9-0.20260405004919-ca62d12c383d05 Apr 2026 pre-releaseNothing published for this version
-
v1.0.9-0.20260404092727-445ac1066f5a04 Apr 2026 pre-releaseNothing published for this version
-
v1.0.9-0.20260402181337-3b89252feffb02 Apr 2026 pre-releaseNothing published for this version
-
v1.0.9-0.20260326160300-9023469c749526 Mar 2026 pre-releaseNothing published for this version
-
v1.0.809 Mar 2026Release notes
Open source →What's Changed
- Use case-insensitive matching for Git error "Not a valid object name" by @mdferdousalam in #389
- Add --fail-on-violation flag to exit non-zero when violations are detected by @mbarbero in #392
- Fix SARIF formatter silently dropping findings from build dependencies by @mbarbero in #393
New Contributors
- @mdferdousalam made their first contribution in #389
- @mbarbero made their first contribution in #392
Full Changelog: v1.0.7...v1.0.8
-
v1.0.702 Feb 2026Release notes
Open source →What's Changed
- Add more structured metadata fields for programmatic access of LOTP targets by @fproulx-boostsecurity in #386
Full Changelog: v1.0.6...v1.0.7
-
v1.0.7-0.20260130185543-64833302a77c30 Jan 2026 pre-releaseNothing published for this version
-
v1.0.613 Jan 2026Release notes
Open source →What's Changed
- Add structured metadata fields to findings for programmatic access by @fproulx-boostsecurity in #385
Full Changelog: v1.0.5...v1.0.6
-
v1.0.509 Jan 2026Release notes
Open source →What's Changed
- Add GHSA-pwf7-47c3-mfhx to OSV advisories database by @kawsarahmedbhuiyan in #381
- Add ubuntu-slim as built-in GitHub Actions runner by @Copilot in #383
- Fix SARIF validation errors for GitHub CodeQL upload by @Copilot in #384
New Contributors
- @kawsarahmedbhuiyan made their first contribution in #381
Full Changelog: v1.0.4...v1.0.5
-
v1.0.428 Oct 2025Release notes
Open source → -
v1.0.328 Oct 2025Nothing published for this version
-
v1.0.3-0.20251027201053-e2f9bd6b784827 Oct 2025 pre-releaseNothing published for this version
-
v1.0.227 Oct 2025Nothing published for this version
-
v1.0.2-0.20251027180105-8f3b2fdb730027 Oct 2025 pre-releaseNothing published for this version
-
v1.0.2-0.20251009193345-c861b1b13e3009 Oct 2025 pre-releaseNothing published for this version
-
v1.0.2-0.20251009145258-e604ca19e54709 Oct 2025 pre-releaseNothing published for this version
-
v1.0.2-0.20251008205509-078da2736f1408 Oct 2025 pre-releaseNothing published for this version
-
v1.0.106 Oct 2025Nothing published for this version
-
v0.18.1-0.20251003191153-fd2979addaf403 Oct 2025 pre-releaseNothing published for this version
-
v0.18.1-0.20251002163417-c0c56d0707a002 Oct 2025 pre-releaseNothing published for this version
-
v0.18.1-0.20250602135000-68f289d615c102 Jun 2025 pre-releaseNothing published for this version
-
v0.18.002 Jun 2025Nothing published for this version
-
v0.17.1-0.20250507201717-13090e16f33107 May 2025 pre-releaseNothing published for this version
-
v0.17.1-0.20250425182712-cee72a96707d25 Apr 2025 pre-releaseNothing published for this version
-
v0.17.018 Apr 2025Nothing published for this version
-
v0.16.113 Feb 2025Nothing published for this version
-
v0.16.1-0.20241211144846-a3abbda9195c11 Dec 2024 pre-releaseNothing published for this version
-
v0.16.1-0.20241204223449-fa1914ec938804 Dec 2024 pre-releaseNothing published for this version
-
v0.16.022 Nov 2024Nothing published for this version
-
v0.15.3-0.20241122160445-4d52b8ec756622 Nov 2024 pre-releaseNothing published for this version
-
v0.15.3-0.20241121143908-eaa5c38b227a21 Nov 2024 pre-releaseNothing published for this version
-
v0.15.3-0.20241121110436-7ec98202de5721 Nov 2024 pre-releaseNothing published for this version
-
v0.15.3-0.20241120195026-871a8db649fd20 Nov 2024 pre-releaseNothing published for this version
-
v0.15.224 Oct 2024Nothing published for this version
-
v0.15.2-0.20241024200935-160d529d7e6524 Oct 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240920135559-efcfd9729ac520 Sep 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240918213800-1b0f7386bb4418 Sep 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240918212722-ad96eeebedaa18 Sep 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240918150436-a6dcf6c3ed1c18 Sep 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240917172519-28fc7a33566a17 Sep 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240916155829-d8229b99f85516 Sep 2024 pre-releaseNothing published for this version
-
v0.15.2-0.20240909153952-f37cc59b93aa09 Sep 2024 pre-releaseNothing published for this version
-
v0.15.109 Sep 2024Nothing published for this version
-
v0.15.1-0.20240828221414-eb0379d0a19728 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240827190342-233dc8aaad7c27 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240826154444-42eb8de6dfa626 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240821205829-cbbc2b2326d621 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240815154950-6ff057c2218115 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240812174851-9ef84c1a981b12 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240810134303-fdc220eea3c410 Aug 2024 pre-releaseNothing published for this version
-
v0.15.1-0.20240809211501-e259b09e5f9509 Aug 2024 pre-releaseNothing published for this version
-
v0.15.002 Aug 2024Nothing published for this version